An issue in the cp_bbs_sig function in relic/src/cp/relic_cp_bbs.c of Relic relic-toolkit 0.6.0 allows a remote attacker to obtain sensitive information and escalate privileges via the cp_bbs_sig function.
References
Link | Resource |
---|---|
https://gist.github.com/liang-junkai/1b59487c0f7002fa5da98035b53e409f | Third Party Advisory |
https://github.com/liang-junkai/Relic-bbs-fault-injection | Exploit Mitigation Patch Third Party Advisory |
https://github.com/relic-toolkit/relic/issues/284 | Issue Tracking Vendor Advisory |
https://gist.github.com/liang-junkai/1b59487c0f7002fa5da98035b53e409f | Third Party Advisory |
https://github.com/liang-junkai/Relic-bbs-fault-injection | Exploit Mitigation Patch Third Party Advisory |
https://github.com/relic-toolkit/relic/issues/284 | Issue Tracking Vendor Advisory |
Configurations
History
21 Nov 2024, 08:38
Type | Values Removed | Values Added |
---|---|---|
References | () https://gist.github.com/liang-junkai/1b59487c0f7002fa5da98035b53e409f - Third Party Advisory | |
References | () https://github.com/liang-junkai/Relic-bbs-fault-injection - Exploit, Mitigation, Patch, Third Party Advisory | |
References | () https://github.com/relic-toolkit/relic/issues/284 - Issue Tracking, Vendor Advisory |
08 Feb 2024, 20:11
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
CPE | cpe:2.3:a:relic_project:relic:0.6.0:*:*:*:*:*:*:* | |
First Time |
Relic Project
Relic Project relic |
|
CWE | CWE-74 | |
References | () https://gist.github.com/liang-junkai/1b59487c0f7002fa5da98035b53e409f - Third Party Advisory | |
References | () https://github.com/relic-toolkit/relic/issues/284 - Issue Tracking, Vendor Advisory | |
References | () https://github.com/liang-junkai/Relic-bbs-fault-injection - Exploit, Mitigation, Patch, Third Party Advisory |
01 Feb 2024, 07:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-02-01 07:15
Updated : 2024-11-21 08:38
NVD link : CVE-2023-51939
Mitre link : CVE-2023-51939
CVE.ORG link : CVE-2023-51939
JSON object : View
Products Affected
relic_project
- relic
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')